Trigger: Use when working with Google Cloud Google Cloud Recipe Onboarding — setup, configuration, and best practices.
Onboarding to Google Cloud
This skill provides a streamlined, non-interactive "happy path" for a singleton developer to get started with Google Cloud. It covers everything from environment verification and authentication to project selection, billing account linkage, and downstream safety chaining.
[!IMPORTANT]
For autonomous agents executing this skill:
- Check-Before-Mutate Audits: Always perform silent pre-execution state audits prior to proposing or executing any project or billing changes.
- Single-Question Policy: Ask the user for exactly one operational parameter or confirmation at a time during interactive execution.
- Non-Interactive Output: Append non-interactive overrides (
--quiet, --format="json") to all mutation commands to guarantee deterministic, machine-parseable outputs and prevent terminal hangs.
- First Turn Interaction Rules (Trigger Turn): When the developer first triggers this skill with a general onboarding request (e.g. says "I want to get started with Google Cloud"):
- Preamble Guidance: Proactively include a short orienting preamble guiding the developer to create a Google Cloud account (pointing to the console at
https://console.cloud.google.com/) and run gcloud auth login to authorize their workstation, even if they appear to be already logged in.
- First Turn Single-Question: Perform pre-flight audits silently, but do not present a complete parameters summary table or ask for final consent in the first turn. Instead, ask the developer exactly one initial operational question (e.g., "Would you like to reuse an existing active project, or create a brand new one?").
Note: If the developer's initial prompt explicitly states "I approve the onboarding configuration", "Let's proceed with onboarding", or requests a dry-run plan (e.g., "Show me the exact plan or dry-run commands"), bypass the general preamble and initial question, and proceed directly to the requested step.
Overview
For an individual developer, onboarding to Google Cloud involves verifying local terminal tools, establishing an authenticated session, selecting or instantiating a workspace (Project), and linking it to an active billing account. Google Cloud offers a Free Tier and a Free Trial with $300 in credits for first-time users. Learn more here.
Prerequisites
- A personal Google Account (e.g.,
@gmail.com) or Google Workspace / Cloud Identity account.
- A valid payment method (credit card or bank account) required for identity verification and to activate the $300 Free Trial credit introduced in the Overview.
Steps
Section 1: Verify Host Tooling Setup
Before soliciting input or proposing mutations, silently audit the host system's active tooling and environment status.
Check if the gcloud CLI binary is installed and accessible:
which gcloud
Check if there is an active authenticated identity session:
gcloud auth list --format="json"
If the pre-execution audit for which gcloud returns a valid path, proceed directly to Section 2: Authenticate and Route Session.
If the binary is missing, halt execution and direct the agent/developer to the gcloud skill or official Google Cloud CLI Installation Guide for setup and authentication instructions before retrying.
Section 2: Authenticate and Route Session
Authorize the gcloud CLI to access Google Cloud using the developer's Google Account, and verify that the account is appropriate for standalone developer onboarding.
Execute Credentials Authentication:
gcloud auth login
[!IMPORTANT]
New User / Unauthenticated Guidance:
If the pre-execution state audits or command failures confirm that the developer is unauthenticated (e.g., gcloud auth list is empty or active credentials are missing):
- Guide them to create a Google Cloud account by navigating to the Google Cloud Console.
- Instruct them to execute the
gcloud auth login command to authorize their local workstation terminal session.
- Do not attempt project creation or resource configuration until authentication is completed successfully.
Verify Active Identity:
gcloud config get-value account --format="json"
Programmatic Enterprise Routing Guardrail:
Before proceeding, verify if the account is bound to a corporate organization, as enterprise setups must follow a different architecture:
gcloud organizations list --format="json"
- Note that new Free Trial accounts automatically receive a Self-Owned Organization (SOO). To distinguish between a personal Free Trial account and an enterprise organization, inspect the JSON output:
- Enterprise Organization (Halt Execution): If the output list contains an organization node where
owner.directoryCustomerId is present (confirming a domain-verified Google Workspace or Cloud Identity organization), or if the user's prompt explicitly mentions corporate landing zones or multi-tenant project structures:
- Personal Account / Free Trial SOO (Proceed): If the output list is empty
[], or if it contains a Self-Owned Organization (where owner.directoryCustomerId is absent and displayName is not a verified domain name), proceed to Section 3: Select or Instantiate Your Google Cloud Project.
Section 3: Select or Instantiate Your Google Cloud Project
Google Cloud resources are organized into Projects. When developers sign up for a Free Trial via the console, Google Cloud automatically creates a default project (e.g., "My First Project"). Always audit the active environment first to reuse existing projects and prevent token-burning collision errors.
Silent Project Discovery:
List active, accessible projects (limited to prevent context window overflow):
gcloud projects list --filter="lifecycleState=ACTIVE" --limit=20 --format="json"
Reuse Existing Project (Recommended):
If the list returns an active project, present it to the developer and propose setting it as the default working project:
gcloud config set project {PROJECT_ID} --quiet
Create Custom Project:
If no projects exist, or if the developer explicitly requests a brand new workspace:
Solicit a custom PROJECT_ID and PROJECT_NAME from the developer (Single-Question Policy).
Structured Confirmation & Consent Gate (Mandatory):
Before running any project creation or billing linkage commands, the agent must present a structured markdown table summarizing the target parameters:
| Parameter |
Value |
| Target Project ID |
{PROJECT_ID} |
| Target Project Name |
{PROJECT_NAME} |
| Active Identity Account |
{ACCOUNT} |
| Target Billing Account ID |
{BILLING_ACCOUNT_ID} |
Ask the user the exact consent query:
"I am ready to initialize your Google Cloud project and link billing. Do you want me to proceed?"
CRITICAL: The agent MUST NOT execute any gcloud projects create or billing link commands during this turn. You must display this table, ask the exact consent query, and strictly stop to wait for the user's positive affirmation.
Project ID Collision Suffix Recovery: If the project creation
command fails because the PROJECT_ID is already taken globally
(returning a PROJECT_ID_COLLISION or ALREADY_EXISTS error):
- Automatically append a random 4-digit suffix (e.g., changing
my-project to my-project-8472).
- Propose this new available project ID to the developer and re-solicit consent before retrying.
Execute Project Creation: Once explicit user consent is confirmed:
gcloud projects create {PROJECT_ID} --name="{PROJECT_NAME}" --quiet --format="json"
Set the active working project:
gcloud config set project {PROJECT_ID} --quiet
Section 4: Verify and Link Billing
To deploy resources on Google Cloud, your project must be linked to an active Cloud Billing account.
Audit Billing Status:
Check if the active project is already linked to a billing account:
gcloud billing projects describe {PROJECT_ID} --format="json"
If the output contains "billingEnabled": true, skip linkage and proceed immediately to Section 5: Skill Chaining (Spend Controls & Workloads).
Discover Available Billing Accounts:
If the project is unlinked, query the available billing account handles linked to the authenticated user identity:
gcloud billing accounts list --format="json"
Link Billing Account:
Propose linking the project to the discovered Billing Account ID, and execute:
gcloud billing projects link {PROJECT_ID} --billing-account={BILLING_ACCOUNT_ID} --format="json"
Section 5: Skill Chaining (Spend Controls & Workloads)
Onboarding setup is now complete. To safeguard your environment and deploy workloads, you can chain to downstream specialized skills:
- Billing Spend Controls:
To avoid accidental cost overruns, consider setting up a programmatic control to automatically disable billing. When billing is disabled, all Google Cloud services and usage in the project are terminated to stop further costs:
- Deploy Workloads: To deploy your first resource, trigger the downstream
specialized skill matching your target application (e.g.,
cloud-run-basics
or
bigquery-basics). If the specialized skill is not locally available,
direct the developer to the corresponding official quickstart, such as the
Cloud Run Container Deployment Quickstart.
Note: Those downstream specialized skills are individually responsible for
dynamically enabling their own required service APIs (e.g.,
run.googleapis.com) inline during execution.
Validation Logic
After completing the onboarding steps, programmatically verify the completed environment state using these diagnostic commands:
Verify CLI Installation:
which gcloud
Verify Authenticated Identity:
gcloud config get-value account
Verify Project Workspace Existence:
gcloud projects describe {PROJECT_ID} --format="json"
Verify Billing Linkage (Ensure the JSON output contains "billingEnabled": true):
gcloud billing projects describe {PROJECT_ID} --format="json"
Additional Resources
1---2name: google-cloud-recipe-onboarding3description: **Trigger**: Use when working with Google Cloud Google Cloud Recipe Onboarding — setup, configuration, and best practices.4---56**Trigger**: Use when working with Google Cloud Google Cloud Recipe Onboarding — setup, configuration, and best practices.78# Onboarding to Google Cloud910This skill provides a streamlined, non-interactive "happy path" for a singleton developer to get started with [Google Cloud](https://cloud.google.com/). It covers everything from environment verification and authentication to project selection, billing account linkage, and downstream safety chaining.1112> [!IMPORTANT]13> For autonomous agents executing this skill:14> 1. **Check-Before-Mutate Audits**: Always perform silent pre-execution state audits prior to proposing or executing any project or billing changes.15> 2. **Single-Question Policy**: Ask the user for exactly **one** operational parameter or confirmation at a time during interactive execution.16> 3. **Non-Interactive Output**: Append non-interactive overrides (`--quiet`, `--format="json"`) to all mutation commands to guarantee deterministic, machine-parseable outputs and prevent terminal hangs.17> 4. **First Turn Interaction Rules (Trigger Turn)**: When the developer first triggers this skill with a general onboarding request (e.g. says "I want to get started with Google Cloud"):18> - **Preamble Guidance**: Proactively include a short orienting preamble guiding the developer to create a Google Cloud account (pointing to the console at `https://console.cloud.google.com/`) and run `gcloud auth login` to authorize their workstation, even if they appear to be already logged in.19> - **First Turn Single-Question**: Perform pre-flight audits silently, but do not present a complete parameters summary table or ask for final consent in the first turn. Instead, ask the developer exactly **one** initial operational question (e.g., *"Would you like to reuse an existing active project, or create a brand new one?"*).20> *Note: If the developer's initial prompt explicitly states "I approve the onboarding configuration", "Let's proceed with onboarding", or requests a dry-run plan (e.g., "Show me the exact plan or dry-run commands"), bypass the general preamble and initial question, and proceed directly to the requested step.*2122---2324## Overview2526For an individual developer, onboarding to Google Cloud involves verifying local terminal tools, establishing an authenticated session, selecting or instantiating a workspace ([Project](https://docs.cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy.md.txt)), and linking it to an active billing account. Google Cloud offers a Free Tier and a Free Trial with $300 in credits for first-time users. [Learn more here](https://docs.cloud.google.com/free/docs/free-cloud-features).2728---2930## Prerequisites3132- A personal Google Account (e.g., `@gmail.com`) or Google Workspace / Cloud Identity account.33- A valid payment method (credit card or bank account) required for identity verification and to activate the $300 Free Trial credit introduced in the Overview.3435---3637## Steps3839### Section 1: Verify Host Tooling Setup4041Before soliciting input or proposing mutations, silently audit the host system's active tooling and environment status.42431. Check if the `gcloud` CLI binary is installed and accessible:44 45 ```bash46 which gcloud47 ```482. Check if there is an active authenticated identity session:49 50 ```bash51 gcloud auth list --format="json"52 ```533. If the pre-execution audit for `which gcloud` returns a valid path, proceed directly to Section 2: Authenticate and Route Session.544. If the binary is missing, halt execution and direct the agent/developer to the [gcloud skill](https://github.com/google/skills/tree/main/skills/cloud/gcloud) or official [Google Cloud CLI Installation Guide](https://docs.cloud.google.com/sdk/docs/install-sdk.md.txt) for setup and authentication instructions before retrying.5556---5758### Section 2: Authenticate and Route Session5960Authorize the gcloud CLI to access Google Cloud using the developer's Google Account, and verify that the account is appropriate for standalone developer onboarding.61621. **Execute Credentials Authentication:**63 64 ```bash65 gcloud auth login66 ```67 > [!IMPORTANT]68 > **New User / Unauthenticated Guidance**:69 > If the pre-execution state audits or command failures confirm that the developer is unauthenticated (e.g., `gcloud auth list` is empty or active credentials are missing):70 > 1. Guide them to create a Google Cloud account by navigating to the [Google Cloud Console](https://console.cloud.google.com/).71 > 2. Instruct them to execute the `gcloud auth login` command to authorize their local workstation terminal session.72 > 3. Do not attempt project creation or resource configuration until authentication is completed successfully.73742. **Verify Active Identity:**75 76 ```bash77 gcloud config get-value account --format="json"78 ```79803. **Programmatic Enterprise Routing Guardrail:**81 Before proceeding, verify if the account is bound to a corporate organization, as enterprise setups must follow a different architecture:82 83 ```bash84 gcloud organizations list --format="json"85 ```86 - Note that new Free Trial accounts automatically receive a Self-Owned Organization (SOO). To distinguish between a personal Free Trial account and an enterprise organization, inspect the JSON output:87 - **Enterprise Organization (Halt Execution)**: If the output list contains an organization node where `owner.directoryCustomerId` is present (confirming a domain-verified Google Workspace or Cloud Identity organization), or if the user's prompt explicitly mentions corporate landing zones or multi-tenant project structures:88 - **Halt execution** of this skill immediately.89 - Route the developer to the official [Google Cloud Setup guided flow](https://docs.cloud.google.com/docs/enterprise/cloud-setup.md.txt).90 - **Personal Account / Free Trial SOO (Proceed)**: If the output list is empty `[]`, or if it contains a Self-Owned Organization (where `owner.directoryCustomerId` is absent and `displayName` is not a verified domain name), proceed to Section 3: Select or Instantiate Your Google Cloud Project.9192---9394### Section 3: Select or Instantiate Your Google Cloud Project9596Google Cloud resources are organized into **Projects**. When developers sign up for a Free Trial via the console, Google Cloud automatically creates a default project (e.g., "My First Project"). Always audit the active environment first to reuse existing projects and prevent token-burning collision errors.97981. **Silent Project Discovery:**99 List active, accessible projects (limited to prevent context window overflow):100 101 ```bash102 gcloud projects list --filter="lifecycleState=ACTIVE" --limit=20 --format="json"103 ```1042. **Reuse Existing Project (Recommended):**105 If the list returns an active project, present it to the developer and propose setting it as the default working project:106 107 ```bash108 gcloud config set project {PROJECT_ID} --quiet109 ```1103. **Create Custom Project:**111 If no projects exist, or if the developer explicitly requests a brand new workspace:112 - Solicit a custom `PROJECT_ID` and `PROJECT_NAME` from the developer (Single-Question Policy).113 - **Structured Confirmation & Consent Gate (Mandatory)**:114 Before running any project creation or billing linkage commands, the agent **must** present a structured markdown table summarizing the target parameters:115 | Parameter | Value |116 | :--- | :--- |117 | Target Project ID | `{PROJECT_ID}` |118 | Target Project Name | `{PROJECT_NAME}` |119 | Active Identity Account | `{ACCOUNT}` |120 | Target Billing Account ID | `{BILLING_ACCOUNT_ID}` |121122 Ask the user the exact consent query:123 `"I am ready to initialize your Google Cloud project and link billing. Do you want me to proceed?"`124125 **CRITICAL**: The agent **MUST NOT** execute any `gcloud projects create` or billing link commands during this turn. You must display this table, ask the exact consent query, and **strictly stop** to wait for the user's positive affirmation.126 - **Project ID Collision Suffix Recovery**: If the project creation127 command fails because the `PROJECT_ID` is already taken globally128 (returning a `PROJECT_ID_COLLISION` or `ALREADY_EXISTS` error):129 - Automatically append a random 4-digit suffix (e.g., changing `my-project` to `my-project-8472`).130 - Propose this new available project ID to the developer and re-solicit consent before retrying.131 - **Execute Project Creation**: Once explicit user consent is confirmed:132 133 ```bash134 gcloud projects create {PROJECT_ID} --name="{PROJECT_NAME}" --quiet --format="json"135 ```136 - Set the active working project:137 138 ```bash139 gcloud config set project {PROJECT_ID} --quiet140 ```141142---143144### Section 4: Verify and Link Billing145146To deploy resources on Google Cloud, your project must be linked to an active Cloud Billing account.1471481. **Audit Billing Status:**149 Check if the active project is already linked to a billing account:150 151 ```bash152 gcloud billing projects describe {PROJECT_ID} --format="json"153 ```1542. If the output contains `"billingEnabled": true`, skip linkage and proceed immediately to Section 5: Skill Chaining (Spend Controls & Workloads).1553. **Discover Available Billing Accounts:**156 If the project is unlinked, query the available billing account handles linked to the authenticated user identity:157 158 ```bash159 gcloud billing accounts list --format="json"160 ```1614. **Link Billing Account:**162 Propose linking the project to the discovered Billing Account ID, and execute:163 164 ```bash165 gcloud billing projects link {PROJECT_ID} --billing-account={BILLING_ACCOUNT_ID} --format="json"166 ```167168---169170### Section 5: Skill Chaining (Spend Controls & Workloads)171172Onboarding setup is now complete. To safeguard your environment and deploy workloads, you can chain to downstream specialized skills:1731741. **Billing Spend Controls:**175 To avoid accidental cost overruns, consider setting up a programmatic control to automatically disable billing. When billing is disabled, all Google Cloud services and usage in the project are terminated to stop further costs:176- Direct the developer to the official [Disable Billing Usage with Notifications Guide](https://docs.cloud.google.com/billing/docs/how-to/disable-billing-with-notifications.md.txt), which provides detailed instructions on how to automatically shut down billing when costs exceed the project budget.1772. **Deploy Workloads**: To deploy your first resource, trigger the downstream178 specialized skill matching your target application (e.g.,179 [cloud-run-basics](https://github.com/google/skills/blob/main/skills/cloud/cloud-run-basics)180 or `bigquery-basics`). If the specialized skill is not locally available,181 direct the developer to the corresponding official quickstart, such as the182 [Cloud Run Container Deployment Quickstart](https://docs.cloud.google.com/run/docs/quickstarts/deploy-container.md.txt).183 *Note: Those downstream specialized skills are individually responsible for184 dynamically enabling their own required service APIs (e.g.,185 run.googleapis.com) inline during execution.*186187---188189## Validation Logic190191After completing the onboarding steps, programmatically verify the completed environment state using these diagnostic commands:1921931. **Verify CLI Installation:**194 195 ```bash196 which gcloud197 ```1982. **Verify Authenticated Identity:**199 200 ```bash201 gcloud config get-value account202 ```2033. **Verify Project Workspace Existence:**204 205 ```bash206 gcloud projects describe {PROJECT_ID} --format="json"207 ```2084. **Verify Billing Linkage** (Ensure the JSON output contains `"billingEnabled": true`):209 210 ```bash211 gcloud billing projects describe {PROJECT_ID} --format="json"212 ```213214---215216## Additional Resources217218- [Google Cloud Getting Started landing page](https://docs.cloud.google.com/docs/get-started.md.txt)219- [Google Cloud overview](https://docs.cloud.google.com/docs/overview.md.txt)220- [Google Cloud Free Program](https://docs.cloud.google.com/free/docs/free-cloud-features)221- [Google Cloud Cloud Setup guided flow](https://docs.cloud.google.com/docs/enterprise/cloud-setup.md.txt)